Back to News
Market Impact: 0.35

Gartner Calls For Pause on AI Browser Use

Artificial IntelligenceCybersecurity & Data PrivacyTechnology & InnovationManagement & GovernanceAnalyst Insights
Gartner Calls For Pause on AI Browser Use

Gartner advises enterprises to block AI browsers until their security risks can be adequately managed, warning in a report that default AI browser settings prioritize user experience over security and expose firms to prompt injection, rogue-agent actions, credential theft and phishing, staff bypassing training, erroneous corporate purchases and exfiltration of sensitive data to cloud AI services. The firm cautions that eliminating these risks is unlikely and that organizations with low risk tolerance may need long-term blocks; recent research from SquareX and Cato Networks has highlighted prompt-injection, malicious workflows and a “HashJack” URL-based attack that can weaponize legitimate sites against AI browsers. Security practitioners recommend against blanket bans as unsustainable, instead urging targeted risk assessments of the underlying AI services and development of playbooks and oversight to enable measured adoption while protecting corporate assets.

Analysis

Gartner has recommended that enterprises block AI browsers until associated risks can be adequately managed in its report "Cybersecurity Must Block AI Browsers for Now," highlighting that default AI browser settings "prioritize user experience over security." The report lists concrete failure modes including indirect prompt injection via rogue agents, erroneous agent actions from "inaccurate reasoning," credential theft through phishing redirects, employees bypassing cybersecurity training, incorrect corporate purchases (e.g., booking wrong flights) and loss of sensitive corporate data to cloud AI services. Independent research cited in the article — a October SquareX study and a subsequent Cato Networks disclosure — corroborates these vulnerabilities, identifying prompt injection, malicious workflows and a "HashJack" URL-based exploit that can weaponize legitimate sites to induce misinformation, phishing links and data exfiltration. Those findings indicate attackers can exploit agentic behaviors and default configurations without breaching backend infrastructure, raising the bar for enterprise controls. Gartner and practitioners conclude that eliminating these risks is unlikely and that low-risk-tolerance organizations may need long-term blocks, while advising measured adoption via service-level risk assessments and playbooks to govern AI agents. For investors this creates near-term policy and adoption headwinds for AI-browser vendors, a likely acceleration in enterprise spend on cybersecurity and governance tooling, and elevated execution risk for companies pushing rapid AI-browser rollouts absent robust controls.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

moderately negative

Sentiment Score

-0.50

Key Decisions for Investors

  • Engage portfolio companies to immediately inventory AI-browser usage and data flows, mandate risk assessments of the underlying AI services and enforce temporary restrictions where sensitive data exposure is material
  • Increase exposure to enterprise cybersecurity, monitoring and governance tooling providers that enable playbooks and agent protection, as these are likely to see accelerated spend
  • Monitor vendor-specific adoption metrics, security disclosures and default-configuration changes for AI-browser products and be prepared to mark down valuations for firms reliant on rapid, unsecured enterprise adoption
  • Consider short-term defensive hedges or reduced exposure to companies with high revenue dependency on AI-browser penetration until independent security audits and formal corporate playbooks are in place